Vulnerabilities and security researches forsimple-wp-events simple-wp-events
Direction: ascendingApr 06, 2025
Simple WP Events # CVE-2025-32193
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 04, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMinds Simple WP Events allows Stored XSS. This issue affects Simple WP Events: from n/a through 1.8.17.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Apr 09, 2025
Simple WP Events # CVE-2025-2004
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 08, 2025
- Research Description
- The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpe_delete_file AJAX action in all versions up to, and including, 1.8.17. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
- Affected versions
-
Min -, max -.
- Status
-
vulnerable